CVE-2024-11054: SourceCodester Simple Music Cloud Community System ajax.php unrestricted upload
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11054?
CVE-2024-11054 is classified as a critical vulnerability.
How does CVE-2024-11054 affect the Simple Music Cloud Community System?
CVE-2024-11054 affects the /music/ajax.php?action=signup file, allowing for unrestricted file uploads.
What is the vector of attack for CVE-2024-11054?
The vulnerability can be exploited by manipulating the pp argument in the signup action.
Can CVE-2024-11054 lead to remote code execution?
Yes, the unrestricted file upload could potentially allow for remote code execution.
How can I mitigate the risks associated with CVE-2024-11054?
To mitigate CVE-2024-11054, ensure you apply the latest security patches and validate file uploads properly.